Our Support
for Your Business

Our Support Options

STEP 3 · TECHNICAL SUPPORT

Protection kept in tune as your network grows

WanGuard deployments and networks are subject to constant change, with prefixes, services and traffic continuing to grow. Keeping protection properly tuned is therefore continuous work, not a one-off deployment. From GOLD upwards it is carried out by the ITORO team. In the SILVER package it remains with the client technical team.

Support tiers and the tasks each one covers
Support tasks SILVEREntry GOLD★ System care GOLD +Weekends & holidays PLATINUMFull handover
Support availability Business daysMon–Fri 7 days a weekweekends and holidays too 7 days a weekweekends and holidays too
Response to a request Next business day Same day Same day
Email support covering operation of and questions about the WanGuard system and Linux only Including critical CVE updates and updates twice a year, together with reminders of key dates such as an approaching WanGuard licence expiry.
DDoS threshold recommendations, backups · false-positive advice
Automatic recovery of sensors and filters ITORO monitors the state of all WanGuard system processes and responds in the event of a failure, restoring sensors and filters.
Full WanGuard server load telemetry Continuous measurement of all Linux system and WanGuard protection parameters: CPU, memory, disk and network interface load. In the event of overload or irregularities we respond before they affect DDoS protection.
Active attack monitoring by ITORO We analyse attacks recorded in the system on an ongoing basis and optimise detection rules so that WanGuard recognises genuine attacks rather than false positives. At the same time we limit the impact of protection on legitimate traffic.
Zoom sessions on WanGuard operation and configuration Anomaly review, detection threshold settings, configuration changes and consultation for the technical team.
Configuration changes in WanGuard carried out by ITORO
Threshold coverage audit: report listing the gaps to close The report identifies networks without a complete set of detection thresholds, the recommended order of remediation and values ready to be entered in the console.
Board report: everything the board needs to know A document for decision-makers: the scale and frequency of attacks, the state of protection and other parameters relevant from the board perspective. Limited technical depth, focused on the current situation in the network and how the organisation handles threats. Issued at any cadence, from weekly to annual.
Network security report: externally visible threats set against attack telemetry We combine reports from several external CERT-type sources with attack telemetry in your network. The result is a summary of priority actions: which hosts to block, which services to restrict and where open ports allow the network to be used for attacks on other entities, which also raises the risk of return attacks.
Full administration of the WanGuard system The ITORO team takes over complete administration of the WanGuard system.
Scope of care 4 of 11 items 10 of 11 items 11 of 11 items
Pricing €275 /month annually in advance €3,025
12 months for the price of 11
€1,800 /month annually in advance €19,800
12 months for the price of 11
€4,000 /month annually in advance €44,000
12 months for the price of 11
Choosing the level of care

The choice comes down to how much day-to-day operation of the system stays with the client team.

scope covered by ITOROstays with the client team
SILVER 4 of 11 items The client team runs the system on its own and occasionally needs the backing of DDoS attack specialists.
GOLD 10 of 11 items The client team is not in a position to run day-to-day operation of the system and hands it over to ITORO.
GOLD + 10 of 11 items Support is also required outside business days, seven days a week.
PLATINUM 11 of 11 items Administration of the system is to be handed over in full.
Package scope and the number of protected networks. Standard packages cover care of the client network. If protection is to cover multiple networks or multiple entities, for example where an operator provides protection to its own customers, the workload grows with the number and nature of the protected networks and requires assessment in each case. In such cases we prepare an individual quotation.
Emergency support

Under attack? 24/7 rapid response

When an attack is live, minutes matter. Our emergency package gives you a direct line to ITORO engineers and a defined escalation path, day or night.

  • 24/7 contact for active DDoS incidents
  • Protection online in as little as 2 hours when your server & router are prepared (RTBH / BGP FlowSpec)
  • Hands-on tuning of WanGuard, FlowSpec and RTBH during the attack
  • Priority handling for GOLD / PLATINUM customers
Get emergency help
Reporting

Reports when you need them

We don't flood you with paperwork after every event. When an incident must be reported to a regulator or government agency, ITORO prepares the documentation on request, with the exact scope, depth and format agreed in advance with sales so it meets your country's and agency's requirements.

  • Attack timeline: start, peak, vectors and duration
  • Traffic evidence and volumetric graphs (pps / bps)
  • What was mitigated, how, and the impact avoided
  • Regulatory summaries (e.g. NIS2) tuned to your jurisdiction, provided under the emergency package
  • Recommendations to harden against the next attack
Compliance · EU NIS2 Directive (2022/2555)

DDoS resilience is now a legal obligation

NIS2 makes DDoS protection and incident reporting mandatory for ISPs, telecoms and digital infrastructure across the EU. Here is what the directive asks for, and how ITORO covers it.

Article 21

Technical & organizational measures

Operators must take appropriate, proportionate measures to manage risks to their networks, including protection against availability attacks such as DDoS.

How ITORO covers it: WanGuard detection paired with Juniper MX line-rate filtering, BGP FlowSpec and RTBH: tuned to your network so attacks are stopped, not just observed.

Article 23: 24h / 72h / 1 month

Incident reporting

Significant incidents must be reported to the national CSIRT within 24 hours (early warning), 72 hours (assessment) and one month (final report).

How ITORO covers it: We prepare the attack timelines, traffic evidence and post-incident reports you need to meet those deadlines: see the reports section below.

Governance

Management accountability

Senior management is directly accountable for cybersecurity risk management and can be held liable for non-compliance.

How ITORO covers it: Documented, tested DDoS protection and a clear 24/7 escalation path give management defensible evidence of due diligence.

Essential & important entities

Broad scope & real penalties

NIS2 covers ISPs, telecoms, cloud, data centers and digital infrastructure. Fines reach up to €10M or 2% of global annual turnover.

How ITORO covers it: ITORO gets you compliant on the resilience side before it is tested, as an Andrisoft Gold Partner with network practice going back to 2005.

Informational summary only, not legal advice. NIS2 was transposed into national law across EU member states; check your local implementation for exact obligations and deadlines.

Is Your Business Safe from DDoS attacks?

DDoS attacks can strike at any time. Don't wait, be proactive in your defense.

See Plans & Pricing